Pith. sign in

REVIEW 4 cited by

Trust No AI: Prompt Injection Along The CIA Security Triad

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2412.06090 v1 pith:U3CMRNJ5 submitted 2024-12-08 cs.CR cs.AIcs.LG

classification cs.CRcs.AIcs.LG
keywords injectionprompttriadcybersecuritydocumentedexploitslargereal-world
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The CIA security triad - Confidentiality, Integrity, and Availability - is a cornerstone of data and cybersecurity. With the emergence of large language model (LLM) applications, a new class of threat, known as prompt injection, was first identified in 2022. Since then, numerous real-world vulnerabilities and exploits have been documented in production LLM systems, including those from leading vendors like OpenAI, Microsoft, Anthropic and Google. This paper compiles real-world exploits and proof-of concept examples, based on the research conducted and publicly documented by the author, demonstrating how prompt injection undermines the CIA triad and poses ongoing risks to cybersecurity and AI systems at large.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting

    cs.CR 2026-07 conditional novelty 7.0 of 10

    Attackers can pre-register resource names that LLMs predictably hallucinate, turning agentic AI assistants into unwitting consumers of malicious promptware payloads.

  2. Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous

    cs.CR 2025-08 conditional novelty 6.0 of 10

    Malicious calendar invites and emails can poison Gemini's context, enabling data exfiltration, app control, and physical-world actions.

  3. SAIF: A Comprehensive Framework for Evaluating the Risks of Generative AI in the Public Sector

    cs.AI 2025-01 conditional novelty 5.0 of 10

    SAIF is a proposed framework that generates multimodal test prompts from a risk taxonomy, jailbreak tricks, and prompt styles to evaluate generative AI risks in the public sector.

  4. Logic layer Prompt Control Injection (LPCI): A Novel Security Vulnerability Class in Agentic Systems

    cs.CR 2025-07 reject novelty 3.0 of 10

    LPCI is presented as a new vulnerability class for agentic LLMs, but prior work already covers memory-based prompt injection and the paper's own numbers contain errors.

Pith tools